Law / Ireland

Data Protection Act 2018

Data Protection Act 2018 (No. 7 of 2018)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

A comprehensive regime rule binding public and private bodies.

As of 24 August 2026.

What it requires

  • Establish and document a lawful basis under General Data Protection Regulation (GDPR) Article 6 before processing any personal data of a person in Ireland.
  • Expect the Data Protection Commission to act as lead supervisory authority under the one-stop-shop mechanism if your EU establishment is in Ireland, for any cross-border processing you carry out.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Data Protection Act 2018 sections 144 to 146 create offences separate from the GDPR Article 83 administrative fines regime. Section 144 makes it an offence for a processor, or an employee or agent of a processor, to disclose personal data without the controller's prior authority. Section 145 makes it an offence to obtain personal data without the controller's or processor's authority and then disclose, sell, or offer to sell it. Section 146 extends liability to a director, manager, secretary or other officer of a body corporate where the offence is committed with that person's consent or connivance, or is attributable to that person's neglect. Each offence carries, on conviction on indictment, a fine not exceeding EUR 50,000 or imprisonment for up to 5 years, or both, and on summary conviction a class A fine or imprisonment for up to 12 months, or both.

Penalty structure

GDPR Article 83(5) sets the higher fine tier, up to EUR 20,000,000 or 4% of total worldwide annual turnover, for infringements including the Article 9 special category rules, the Article 12 to 22 data subject rights, and the Chapter V transfer rules. The lower Article 83(4) tier, up to EUR 10,000,000 or 2% of turnover, applies instead to the Article 25 to 39 controller and processor obligations, including the Article 33 and 34 breach notification duties. Data Protection Act 2018 section 141(4) caps the administrative fine the Commission may impose on a public authority or public body that does not act as an undertaking within the meaning of the Competition Act 2002 at EUR 1,000,000.

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Data Protection Commission (An Coimisiún um Chosaint Sonraí), Ireland's supervisory authority under the GDPR and the Data Protection Act 2018.

Enforcement record

Counts the Data Protection Commission's finalised large scale statutory inquiries that resulted in an administrative fine in calendar year 2025 (4), per the Commission's own press release announcing its 2025 Annual Report, published 2026-06-30: two fines totalling EUR 530 million against TikTok Technology Limited over transfers of EEA user data to China, and a EUR 550,000 fine against the Department of Social Protection over biometric facial matching in the Public Services Card registration process; fines_per_year of just over EUR 530.77 million is the release's own stated total for the year. Public enforcement actions only, counted from the Commission's own announcement rather than a private tracker; the release does not restate a cumulative since-2018 total, so total_fines is not recorded here. This is the regime's own enforcement record, not specific to this instrument.

As of
2 September 2026
Currency
EUR
Source link
https://www.dataprotection.ie/en/data-protection-commission-publishes-2025-annual-report
Fines per year
530,770,000
Actions per year
4

What it reaches

Obligation class

Consent, Disclosure, Data subject rights, Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The General Data Protection Regulation (GDPR) applies directly in Ireland, and the Data Protection Act 2018 (DPA 2018), No. 7 of 2018, gives it domestic effect: Part 3 supplies Ireland's national derogations and exemptions, Part 2 establishes the Data Protection Commission (DPC) as supervisory authority, and Part 6 supplies the enforcement architecture; Part 5 transposes the Law Enforcement Directive and is not the GDPR regime.

Because most large United States technology companies base their EU headquarters in Ireland, the DPC is the lead supervisory authority under the GDPR one-stop-shop mechanism for most of their cross-border processing, which makes Irish enforcement practice a de facto reference point for the whole EU, including on how existing privacy law reaches AI training uses of personal data.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

Irish Statute Book, official consolidated text

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app